Privacy notice
This notice describes the data the current application stores and why. It is based on the implemented account, test, analytics and billing models.
Effective 11 August 2026
Account data
The application stores your name, email address, identity-provider user reference, verification and login timestamps, chosen exam, content-language preference and onboarding choices. The identity provider handles credentials and sessions; Abhyaas does not store your password.
Practice and analytics data
We store attempts, saved answers, timing and navigation events, submission status, scores, section and topic performance, result history and leaderboard records. This is used to deliver and score tests, resume an attempt, show your history, enforce the attempt limits and cooldowns each certification states, and calculate analytics supported by real attempts.
Billing data
The application stores which certifications you have bought, the amount and currency charged, the purchase date and status, the payment provider’s payment and customer references, invoice records, and an audit trail of changes to any of it. Card and bank details are handled by the payment provider and are never stored in the Abhyaas database.
Providers
The current architecture uses WorkOS for identity, Dodo Payments for hosted billing and Cloudflare for application hosting and database infrastructure. Each provider may process the information needed to perform its service. Their own notices govern data they collect directly.
Sharing controls
Public result sharing is off until you enable it for a result. Leaderboard display has a separate anonymity preference. Do not treat either control as a substitute for keeping your account credentials private.
Cookies and security records
Session cookies keep you signed in, a locale cookie remembers interface language, and CSRF tokens protect state-changing requests. Security and rate-limit records use hashed identifiers or network buckets rather than storing a raw password or payment credential.
Retention and account closure
Attempt, result, billing and audit records are designed to remain internally consistent. The data model supports anonymising an account instead of deleting linked records, but the current product has no public request channel or self-service closure control. No retention period is claimed until the operator publishes one with its legal identity and privacy contact.